CVE-2026-41904: FreeScout Stored XSS vulnerability in mailbox auto-reply: payload reaches every customer's email client (no CSP), bypassing strip_tags validator with mixed text+HTML content
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply message. The payload is rendered unescaped in the auto-reply email sent to every customer who contacts the mailbox. Email clients do not enforce CSP, so the payload executes in the customer's webmail / mail-client context. This issue has been patched in version 1.8.217.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41904?
CVE-2026-41904 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-41904?
To remediate CVE-2026-41904, upgrade FreeScout to version 1.8.217 or later to patch the vulnerability.
What versions of FreeScout are affected by CVE-2026-41904?
FreeScout versions prior to 1.8.217 are affected by CVE-2026-41904.
What type of vulnerability is CVE-2026-41904?
CVE-2026-41904 is a Stored XSS vulnerability that allows malicious payloads to be sent to customer email clients.
What are the potential impacts of CVE-2026-41904?
The potential impacts of CVE-2026-41904 include unauthorized access to user data and execution of malicious scripts in customer email clients.